CVE-2024-37444: WordPress Defender plugin <= 4.7.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Defender Security defender-security.This issue affects Defender Security: from n/a through <= 4.7.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37444?
CVE-2024-37444 is classified as a missing authorization vulnerability that allows unauthorized access to functionality not properly constrained by ACLs.
How do I fix CVE-2024-37444?
To fix CVE-2024-37444, update WPMU DEV Defender Security to version 4.7.2 or later, which addresses the authorization issues.
What versions are affected by CVE-2024-37444?
CVE-2024-37444 affects WPMU DEV Defender Security versions up to and including 4.7.1.
What functionality is impacted by CVE-2024-37444?
CVE-2024-37444 enables access to functions that should be restricted, potentially compromising security configurations.
Is there a workaround for CVE-2024-37444?
There is no official workaround for CVE-2024-37444; the best solution is to apply the available update.